ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Activecollab | Activecollab | * | 2.3.1 (including) |
References